On 1/26/06, Daniel John Debrunner <[EMAIL PROTECTED]> wrote:
> Francois Orsini (JIRA) wrote:
>
> >     [ 
> > http://issues.apache.org/jira/browse/DERBY-866?page=comments#action_12364090
> >  ]
> >
> > Francois Orsini commented on DERBY-866:
> > ---------------------------------------
>
> > In this case, the password column can just be renamed to something else
> > (i.e. AUTH_INFO), in order to support *not* just a password value
>
> I'm still missing something, you seem keen on having a column that
> returns the hashed password. Do you have some intended use for this?
>
> Besides it being a security risk, I just can't see any use for it.
>

Nope - like I said in a previous reply:

>> But I agree it is still
>> better not to show it at all - what we could do is only show the
>> content IF the authentication scheme/style is different than built-in-
>> or like you say we don't display the column at all.

I agreed about not showing it at all. I was just making another
suggestion in the just above blurb as well as agreeing to your
comment...

> Dan.
>
>
>

Reply via email to